GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
45
Go
3,196
Maven
5,000+
npm
5,000+
NuGet
864
pip
4,483
Pub
12
RubyGems
992
Rust
1,186
Swift
51
Unreviewed advisories
All unreviewed
5,000+
153 advisories
Filter by severity
MediaWiki Incorrect Access Control vulnerability
Moderate
CVE-2019-12467
was published
for
mediawiki/core
(Composer)
May 24, 2022
Symfony Incorrect Access Control
Critical
CVE-2017-11365
was published
for
symfony/security
(Composer)
May 24, 2022
TYPO3 Remote File Disclosure vulnerability in the jumpUrl mechanism
High
CVE-2010-3714
was published
for
typo3/cms
(Composer)
May 17, 2022
Symfony Access Control Vulnerability
Moderate
CVE-2012-6432
was published
for
symfony/symfony
(Composer)
May 17, 2022
Drupal improper access restrictions
Moderate
CVE-2012-2153
was published
for
drupal/drupal
(Composer)
May 17, 2022
TYPO3 Improper Access Control vulnerability
Moderate
CVE-2013-7081
was published
for
typo3/cms-core
(Composer)
May 17, 2022
TYPO3 Improper Access Management in the File Abstraction Layer
Moderate
CVE-2013-4320
was published
for
typo3/cms-core
(Composer)
May 17, 2022
yag and pt_extbase extensions for TYPO3 allow remote attackers to bypass access restrictions
High
CVE-2014-6289
was published
for
dl/yag
(Composer)
May 17, 2022
Drupal Access Control Bypass
High
CVE-2011-2687
was published
for
drupal/core
(Composer)
May 17, 2022
Drupal Form API ignores access restrictions on submit buttons
High
CVE-2016-3165
was published
for
drupal/core
(Composer)
May 17, 2022
Drupal File upload access bypass and denial of service
High
CVE-2016-3162
was published
for
drupal/core
(Composer)
May 17, 2022
Symfony Incorrect Access Control
Moderate
CVE-2015-4050
was published
for
symfony/http-kernel
(Composer)
May 17, 2022
Drupal Node Validation Bypass in the node module API
High
CVE-2008-4793
was published
for
drupal/drupal
(Composer)
May 17, 2022
Mediawiki tarball is missing .htaccess files
Moderate
CVE-2018-13258
was published
for
mediawiki/core
(Composer)
May 14, 2022
Craft CMS Unauthorized View
Moderate
CVE-2017-8383
was published
for
craftcms/cms
(Composer)
May 13, 2022
Drupal access control bypass vulnerability
High
CVE-2017-6919
was published
for
drupal/core
(Composer)
May 13, 2022
Drupal access bypass vulnerability
High
CVE-2017-6930
was published
for
drupal/core
(Composer)
May 13, 2022
Contao Information Disclosure via Access Control Flaws
Moderate
CVE-2018-20028
was published
for
contao/contao
(Composer)
May 13, 2022
Moodle does not use the forceloginforprofiles setting for course-profiles access control
Moderate
CVE-2011-4279
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle does not properly restrict access to category and course data
Moderate
CVE-2011-4300
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle is vulnerable to unauthorized new accounts creation
Moderate
CVE-2010-1616
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle does not consider "don't send" attributes during hub registration
Moderate
CVE-2013-2081
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle allows remote authenticated users to reassign notes
Moderate
CVE-2013-1834
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle does not enforce the forceloginforprofiles setting
Moderate
CVE-2013-1830
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle allows attackers to extract archives to arbitrary directories
Moderate
CVE-2015-2267
was published
for
moodle/moodle
(Composer)
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API